WebIntelligence URL request allows file deletion

webintelligence-url-delete-files (17422) The risk level is classified as MediumMedium Risk

Description:

WebIntelligence could allow a remote authenticated attacker to delete arbitrary files via InfoView, which is the Web-based interface. By sending a specially-crafted URL request using the document ID and the document name variables, a remote unauthorized attacker could bypass access controls and delete arbitrary files.


Consequences:

File Manipulation

Remedy:

For WebIntelligence 2.7.0 to 2.7.2:
Upgrade to the latest Service Pack (SP7 or SP8 or later) and apply the appropriate patch for your system, available from the Business Objects Technical Support Web site. See References.

For WebIntelligence 2.7.3:
Apply the update for your system, available from the Business Objects Technical Support Web site. See References.

For WebIntelligence 2.7.4:
Apply the update for your system, available from the Business Objects Technical Support Web site. See References.

References:

  • Corsaire Security Advisory c040527-001: Business Objects WebIntelligence arbitrary document deletion issue.
  • BID-11208: Business Objects WebIntelligence Access Control Bypass File Deletion Vulnerability
  • CVE-2004-0533: Business Objects WebIntelligence 2.7.0 through 2.7.4 only enforces access controls on the client, which allows remote authenticated users to delete arbitrary files on the server via a crafted delete request using the InfoView web client.
  • OSVDB ID: 10016: WebIntelligence Restriction Bypass Arbitrary Document Deletion
  • SA12587: WebIntelligence Document Deletion and Cross-Site Scripting Vulnerabilities

Platforms Affected:

  • BusinessObjects InfoView 5.1.4
  • BusinessObjects InfoView 5.1.5
  • BusinessObjects InfoView 5.1.6
  • BusinessObjects InfoView 5.1.7
  • BusinessObjects InfoView 5.1.8
  • BusinessObjects WebIntelligence 2.7
  • BusinessObjects WebIntelligence 2.7.1
  • BusinessObjects WebIntelligence 2.7.2
  • BusinessObjects WebIntelligence 2.7.3
  • BusinessObjects WebIntelligence 2.7.4

Reported:

Sep 17, 2004

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page